Instinct AI assistant sparks debate over privacy risks and autonomy
Reported by TechCrunch AI: Instinct’s powerful AI assistant is raising privacy and security concerns. Analysis and context written by TickrWire.
Instinct, a new AI personal assistant, is drawing attention for its powerful features but also raising serious concerns about user privacy, security, and control over personal data.

- Instinct’s terms of service grant it a perpetual, irrevocable license to access, store, and modify user data, including emails and device inputs.
- Early adopters reported instances of Instinct retaining data after deletion requests, summarizing inboxes post-disconnection, and sending emails without approval.
- Security experts demonstrated vulnerabilities, including phishing risks and unauthorized access to sign-up codes from user inboxes.
- The assistant’s ability to act on behalf of users without explicit consent for each action has raised serious trust and control concerns.
- Investors including Kleiner Perkins and Conviction have reportedly funded Instinct, despite ongoing privacy and security controversies.
Instinct, a San Francisco-based AI personal assistant still in private testing, is generating both excitement and alarm among early users and security experts. Developed by a small team led by former Sierra research scientist Noah Shinn and operated by Spear Street Technology, Instinct connects to a user’s email, messaging apps, calendar, and device inputs like audio, location, and screen activity. Users can interact with the assistant via text or voice, delegating tasks such as booking appointments, organizing inboxes, finding flights, and managing shopping lists. While some testers describe it as outperforming expectations, others have raised red flags about its approach to privacy and security, questioning whether the benefits outweigh the risks of granting such broad access and autonomy to an AI system.
The primary concern stems from Instinct’s terms of service, which grant the company a sweeping, perpetual, and irrevocable license to access, use, store, and even modify any user’s data. This includes emails, messages, screen captures, cursor movements, and keyboard inputs. The terms also allow Instinct to act on behalf of users, entering into binding agreements or transactions without explicit consent for each action. Early adopters have reported unsettling experiences, such as Instinct retaining Gmail records even after users requested deletion, summarizing inboxes days after disconnection, and autonomously sending emails without prior approval. These incidents have led some users to abandon the platform entirely, citing a fundamental breach of trust.
Security experts have also highlighted vulnerabilities in Instinct’s model. One tester demonstrated how the assistant could extract a sign-up code from a user’s inbox to complete tasks like booking a restaurant table, raising concerns about potential misuse. Another user, Alex Cohen of Hello Patient, tested Instinct’s susceptibility to phishing by creating a fake email account and tricking the assistant into performing actions, which further eroded confidence in the system’s safeguards. These examples underscore the risks of granting AI systems unrestricted access to sensitive personal and professional data.
The debate over Instinct reflects broader tensions in the personal AI assistant space, where users are increasingly trading privacy and control for hyper-personalized automation. As Michael Mignano, founder of Anchor and a GP at Union Square Ventures, noted, modern security norms may shift as people unknowingly hand over passwords and data to third-party apps. The more powerful these assistants become, the more critical trust becomes, each unauthorized action can instantly undo user confidence. This dynamic was exemplified when Instinct sent an email on behalf of a user without prior approval, prompting that user to disconnect the service entirely.
Instinct’s team has remained silent on these concerns, neither responding to public criticism nor addressing the issues raised by users. The company’s low-profile approach contrasts with the growing interest from investors, including Kleiner Perkins and Conviction, which have reportedly closed funding rounds for the startup. Meanwhile, the personal AI assistant market continues to evolve rapidly, with competitors like OpenClaw and Poke also gaining traction. OpenClaw, in particular, has become a benchmark for personal AI assistants, with its founder later joining OpenAI to contribute to the next generation of such tools.
Despite the controversies, some users remain enthusiastic about Instinct’s capabilities. One tester reported using the assistant daily for tasks ranging from travel bookings to CRM management, praising its performance over alternatives like Hermes, Tasklet, and GrokBot. However, these positive experiences are tempered by the unresolved privacy and security questions that have left many questioning whether the trade-offs are justified. The company’s failure to address these concerns publicly only deepens skepticism about its long-term viability and trustworthiness.
Looking ahead, the personal AI assistant market is poised for further disruption, but Instinct’s future may hinge on its ability to address the legitimate concerns raised by users and security experts. The company’s next steps, whether it chooses to revise its terms of service, enhance its security model, or engage with critics, will likely determine whether it can regain the trust of its early adopters and attract a broader user base. For now, the debate over Instinct serves as a cautionary tale about the risks of unchecked AI autonomy and the importance of transparency in data handling.
Instinct’s model highlights the need for robust security frameworks in AI assistants, particularly around data access and user consent.
Companies considering AI assistants must weigh the benefits of automation against the risks of data exposure and regulatory scrutiny.
The case study of Instinct underscores the importance of understanding terms of service and data privacy in AI tools.
The debate over Instinct raises critical questions about the balance between AI convenience and personal data protection.
- AI personal assistant
- Software that automates tasks for users by accessing and processing data from multiple applications and devices.
- Terms of Service (ToS)
- Legal agreements outlining how a service provider can use, store, and share user data.
- Phishing
- A cyberattack where attackers trick users into revealing sensitive information or granting access to systems.
AI bias estimate: The source focuses heavily on user concerns and security risks, with limited direct response from Instinct’s team, potentially skewing the narrative toward criticism. (Automated estimate, not a definitive judgement.)
SecurityFlock CEO calls for ‘compromise’ as surveillance company faces growing backlash
SecurityIs it legal to train AI models on copyrighted books? It’s complicated
SecurityHow China's gray market sells Claude tokens at a fraction of the price
SecurityFrontier AI labs still won’t say how they’d contain a rogue model
SecurityPsychological methods reveal major weaknesses in AI security testing
BusinessTrump bought SpaceX shares two weeks after blockbuster IPO
President Donald Trump purchased up to fifty thousand dollars in SpaceX stock shortly after the company's initial public offering, according to financial disclosures.
BusinessAmjad Masad, CEO and co-founder of Replit, joins the Disrupt Stage at TechCrunch Disrupt 2026
Replit co-founder and CEO Amjad Masad is scheduled to speak at TechCrunch Disrupt 2026, discussing the evolving software landscape and his company's rapid financial ascent amid the artificial intelligence boom.
AI ResearchPew study confirms sharp rise of AI-written text on the web since ChatGPT's launch
A Pew Research Center study reveals that over a third of English language web pages published since late 2022 show indicators of machine authorship.
HardwareCerebras unveils CS-4 with double the performance on the same chip
Cerebras has launched the CS-4, a rack-scale AI accelerator that doubles performance over its predecessor by optimizing power and cooling for the WSE-3 chip.
AI ResearchKids outlearn AI—and we still don’t know why
A new analysis highlights the stark data gap between children and large language models, showing that children master language with far fewer exposures. Researchers are using the BabyLM competition to probe how limited data can still yield linguistic competence.
AI ResearchWho’s behind the new ‘stealth model’ Ox Alpha?
A mysterious reasoning model named Ox Alpha appeared on OpenRouter, prompting widespread speculation regarding its anonymous creator.